SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-60060

MEDIUM · CVSS 6.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The TTSSH2 plugin of Tera Term is vulnerable due to improper handling of length parameter inconsistencies, which can lead to out-of-bounds read/write operations during SSH connections to malicious servers. This vulnerability may allow attackers to access adjacent memory contents, potentially leading to unexpected behavior or crashes of the Tera Term application. Organizations using Tera Term for SSH connections should prioritize addressing this vulnerability to mitigate risks associated with unauthorized data exposure and application instability.

CVE
CVE-2026-60060
Severity
MEDIUM
CVSS
6.3
EPSS
0.18%

Original NVD Description

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.